CVE-2023-51800

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
29/02/2024
Last modified:
16/12/2024

Description

Cross Site Scripting (XSS) vulnerability in School Fees Management System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the main_settings component in the phone, address, bank, acc_name, acc_number parameters, new_class and cname parameter, add_new_parent function in the name email parameters, new_term function in the tname parameter, and the edit_student function in the name parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:school_fees_management_system_project:school_fees_management_system1.0:*:*:*:*:*:*:*:*